| |
|
|
Limited Time!
Parasite: ASpamThis record last updated Tue Sep 20 2005 00:34:14 PLEASE NOTE: Due to the overwhelming extent of this problem and the unbelievable volume of email we have received, we regret that we cannot respond to questions about browser parasites at this time. If you have attempted to contact us about this parasite please accept our apology for not responding. "Thank you's" are always appreciated ;-) DescriptionASpam is remote access trojan implemented as an IE Browser Helper Object. It is not really Unsolicited Commercial Software as it has no known commercial aim, but it is included in the detection script at this site as it is a threat detectable from web pages. VariantsASpam/Amcis: installs the BHO under the filename AMCIS32.DLL, with object name Amcis32. ASpam/Drvman: the file and object name is DRVMAN32 instead and the classid is different. DistributionThe installer ASPAM.EXE was attached to a mass-mailing purported to come from Microsoft (aspam@microsoft.com), offering an anti-spam feature for Outlook Express. The actual author is not currently known. What it doesAdvertisingNo. Privacy violationNo. Security issuesYes. Gives the attacker user-level access to the machine it is installed on. Stability problemsNo. RemovalNo uninstall feature, but many anti-virus tools target the ASpam trojan. Manual removalOpen the registry (Start->Run->regedit) and delete the following keys. For variant Amcis: HKEY_LOCAL_MACHINE\Software\Classes\AMCIS32.IEClass For variant Drvman: HKEY_LOCAL_MACHINE\Software\Classes\DRVMAN32.IEClass (Ignore the ‘DontDelete’ subkey in Browser Helper Objects.) Restart the computer and you should be able to delete the AMCIS32.DLL file in the System folder (to be found inside the Windows folder, ‘System’ under Windows 95/98/Me, ‘System32’ under Windows NT/2000/XP). Links
* Parasite information and detection script by Andrew Clover - www.doxdesk.com, used with permission. For more information about Scumware, Spyware and Parasites, their sources and their cure, visit our About Parasites page and related Tech Links. Visit our new services portal at Allen One for a completely new parasite database format, comming November 2005! |